The Growing Threat
In 2025, global fraud and scam losses hit $579.4 billion, increasing at 9.2% annually since 2023. Authorized push payment scams, including romance frauds and impersonation attacks, accounted for $62 billion, growing at more than double the rate of unauthorized fraud. In EMEA, fraud losses reached $132.9 billion, with $154.4 billion in illicit flows crossing EU borders.
A survey of over 500 anti-financial crime professionals found that 90% reported a rise in AI-driven attacks at their institutions. Criminals adopted AI early, using it to create convincing, personalized fraud at scale. Meanwhile, many financial institutions still rely on outdated detection systems designed for a pre-AI threat environment.
The Lagging Response
The issue isn't a single event but a structural lag that compounds annually:
2023-2025: Fraud scams grow at double the rate of unauthorized fraud, while most banks continue using transaction-level detection models based on historical fraud patterns.
During this period: Criminal networks commoditize fraud infrastructure, selling toolkits that enable high-volume attacks without technical expertise. AI-enabled deepfakes and hyper scams become standard.
By the time victims reach their bank: They've often been manipulated for days or weeks on dating apps or social media. The transaction appears authorized because the victim believes they're sending money to a legitimate recipient.
Post-transaction: Law enforcement receives reports only after harm has occurred. There's no mechanism to share verified scam indicators in real time across telecoms, digital platforms, and financial institutions.
Missing Controls
Lack of consortium-level detection: Most institutions use fraud detection models trained only on their own transaction data, missing cross-institution fraud patterns. A scammer operating across multiple banks appears as isolated activity to each institution.
No cross-industry signal sharing: Banks see scams at the transaction point, while social media platforms and telecoms see the initial contact and manipulation. Without real-time connection, scammers' phone numbers remain active, and fraudulent ads stay live.
Legacy rule-based systems: Traditional detection systems generate high false positives while sophisticated fraud slips through. They're not built to detect authorized push payment fraud, where the transaction itself is legitimate but the fraud occurs upstream.
Explainability gap: Even institutions using AI models face regulatory uncertainty about meeting supervisory model risk management standards. Without explainable AI frameworks, some delay deployment to avoid regulatory scrutiny.
Compliance Requirements
The Bank Secrecy Act requires financial institutions to establish procedures to detect and report suspicious transactions. If your system can't identify patterns across institutions, you're operating with a blind spot.
The FFIEC BSA/AML Examination Manual emphasizes using available data and technology to identify suspicious activity. If consortium data could improve detection accuracy, not using it is a compliance issue.
Payment Services Directive 2 requires strong customer authentication and fraud monitoring for electronic payments. Your fraud monitoring must account for authorized push payment schemes, needing context beyond the transaction.
For AI-based detection, the FFIEC IT Examination Handbook provides guidance on model risk management. Your AI systems must be explainable, auditable, and validated. This requires frameworks that document how models reach decisions and validate accuracy.
Action Steps for Your Team
Evaluate consortium data access now. If your models are trained only on your institution's data, you're missing cross-institution patterns. Machine learning analytics trained on consortium data can detect fraud patterns invisible to single-institution models. Compare your current system against consortium-enhanced detection to measure differences in false positive rates and fraud catch rates.
Incorporate explainability into AI deployment. Don't choose between AI effectiveness and compliance. Use AI to execute complex compliance workflows while maintaining explainability. Document model logic, validation procedures, and decision audit trails before deployment.
Establish cross-industry signal sharing. You can't stop a scam originating on a dating app by monitoring payment transactions alone. Work with industry associations to share verified scam indicators in real-time: phone numbers, malicious URLs, fraudulent ad content. When a telecom blocks a scammer's number and a bank flags the associated account simultaneously, the scam infrastructure breaks down.
Differentiate authorized from unauthorized fraud in metrics. Reporting "fraud losses" as a single number obscures the problem. Authorized push payment fraud requires different controls than card-not-present fraud. Track and resource them separately.
Reduce investigator time on low-value tasks. If fraud analysts spend hours gathering basic information for each alert, you're wasting skilled judgment. Deploy AI for initial triage and information assembly. Investigators should focus on substantive risk assessment.
The threat has outpaced institutional defenses because criminals adopted AI without waiting for regulatory clarity. Your obligation isn't to match their speed but to deploy effective controls using available technology. Consortium data and explainable AI frameworks exist today. The question is whether your institution will use them before the next Suspicious Activity Report (SAR) shows another year of growth.





